Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-07-31 ยท updated: 2026-08-18 ยท tags: [] ยท confidence: not-rated ยท affected_sectors: [] ยท au_impact: false

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

Summary

Blackpoint Cyber detailed HollowFrame (Go-based loader framework) and Matryoshka (Rust-based malware) deployed in a spear-phishing attack on a law firm. The attack chain involves multiple stages including privilege escalation, Defender weakening, and DLL side-loading.

Key Details

  • Date: 2026-07-31
  • Source: The Hacker News
  • Reliability: Tier 2/4 โ€” Established cyber journalism
  • Attack Chain: 1. Spear-phishing โ†’ encrypted archive with LNK 2. Privilege escalation 3. Microsoft Defender weakening 4. DLL side-loading (python.exe / python311.dll)
  • Malware Components:
  • HollowFrame: Go-based loader framework
  • Matryoshka: Rust-based malware with two variants: HTTP-based C2 and GitHub C2

Sources